Description
Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass via crafted HTML page
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an incorrect authorization in the WebProtect component of Google Chrome. Prior to version 152.0.7977.65, a remote attacker can design an HTML page that, when opened by a user, forces the browser to bypass system access restrictions that normally prevent non‑privileged web content from accessing protected APIs. This results in an authorization bypass that could allow the attacker to execute code or retrieve sensitive data from the user’s system.

Affected Systems

Affected systems are installations of Google Chrome older than 152.0.7977.65 on any platform where the WebProtect feature is enabled. The vulnerability is classified under CWE-863.

Risk and Exploitability

The issue has a CVSS score of 4.3 and an EPSS score of < 1%, indicating low severity and a very low but nonzero likelihood of exploitation. It is not listed in the CISA KEV catalog, suggesting no publicly known active exploitation. The vulnerability requires only a crafted HTML page that can be delivered remotely, so the attack vector is remote. A patch is recommended before a deployed exploit emerges.

Generated by OpenCVE AI on August 28, 2026 at 23:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later, which contains the WebProtect authorization fix.
  • In environments where updating is delayed, apply Chrome enterprise policies to disable the WebProtect feature or restrict access to potentially dangerous web content, and quarantine or block locally stored crafted HTML files.
  • Monitor Chrome releases and security advisories for early disclosure of similar WebProtect flaws and consider disabling vulnerable extensions or additional remote‑code‑execution mechanisms.

Generated by OpenCVE AI on August 28, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:40:21.722Z

Reserved: 2026-08-25T06:08:40.843Z

Link: CVE-2026-79077

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:03.510

Modified: 2026-08-31T15:03:16.037

Link: CVE-2026-79077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:15:04Z

Weaknesses